Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64581

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
05/08/2026
Última modificación:
05/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> xfrm: fix sk_dst_cache double-free in xfrm_user_policy()<br /> <br /> xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),<br /> i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with<br /> rcu_dereference_protected(), stores NULL and dst_release()s the old dst.<br /> That is only safe if no other thread modifies sk_dst_cache concurrently.<br /> <br /> For a connected UDP socket that does not hold: the transmit fast path<br /> (udp_sendmsg -&gt; sk_dst_check -&gt; sk_dst_reset) resets the cache locklessly<br /> with an atomic xchg(). A per-socket policy change racing a send can make<br /> both sides observe the same old dst and each dst_release() it, dropping<br /> the socket&amp;#39;s single reference twice and freeing the xfrm_dst bundle while<br /> it is still referenced:<br /> <br /> BUG: KASAN: slab-use-after-free in dst_release<br /> Write of size 4 at addr ffff88801897b6c0 by task exploit/155<br /> Call Trace:<br /> ...<br /> dst_release (... ./include/linux/rcuref.h:109)<br /> xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)<br /> do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)<br /> ip_setsockopt (net/ipv4/ip_sockglue.c:1417)<br /> do_sock_setsockopt (net/socket.c:2368)<br /> __sys_setsockopt (net/socket.c:2393)<br /> __x64_sys_setsockopt (net/socket.c:2396)<br /> do_syscall_64 (arch/x86/entry/syscall_64.c:94)<br /> entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)<br /> <br /> Reachable by an unprivileged user via a user+network namespace.<br /> <br /> Use the atomic sk_dst_reset() so the cache is cleared and released with a<br /> single xchg(): whichever side wins releases the dst once, the other sees<br /> NULL and does nothing. Behaviour is otherwise unchanged.

Impacto